CVE-2021-24507
CRITICALBrainstormforce Astra < 3.5.2 - SQL Injection
Title source: ruleDescription
The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.4420
EPSS Percentile
97.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-89
Status
published
Affected Products (1)
brainstormforce/astra
< 3.5.2
Timeline
Published
Aug 09, 2021
Tracked Since
Feb 18, 2026